New Malicious PyPI Packages used by Lazarus

2024-02-28 JPCERT

https://blogs.jpcert.or.jp/en/2024/02/lazarus_pypi.html

JPCERT/CC found Lazarus-linked malicious PyPI packages that imitated legitimate Python crypto libraries, including typosquatted names around pycrypto. The packages carried an XOR-encoded DLL in test.py that could be decoded and launched through __init__.py, then executed Comebacker with rundll32 and in-memory payload handling. Comebacker posted encoded host data to C2 endpoints such as chaingrown.com/manage/manage.asp and could receive and execute Windows executables in memory. JPCERT/CC tied the tooling to Lazarus through overlap with earlier Comebacker use against security researchers and code traits also seen in BLINDINGCAN, while noting package download counts in the hundreds to low thousands.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 63fb47c3b4693409ebadf8a5179141a… 2024-02-21 2025-02-16
DOMAIN fasttet.com 2024-02-21 2024-07-05
IPv4 91.206.178.125 2023-11-04 2024-07-05
DOMAIN blockchain-newtech.com 2023-12-08 2024-05-28
DOMAIN chaingrown.com 2023-12-08 2024-05-28
HASH 173e6bc33efc7a03da06bf5f8686a89… 2024-02-21 2024-02-28
HASH 956d2ed558e3c6e447e3d4424d6b14e… 2024-02-21 2024-02-28
HASH e05142f8375070d1ea25ed3a31404ca… 2024-02-21 2024-02-28
HASH 85c3a2b185f882abd2cc40df5a1a341… 2024-02-21 2024-02-28
HASH 26437bc68133c2ca09bb56bc011dd1b… 2024-02-21 2024-02-28
HASH 6bba8f488c23a0e0f753ac21cd83dde… 2024-02-21 2024-02-28
HASH a8a5411f3696b276aee37eee0d9bed9… 2024-02-21 2024-02-28
HASH 01c5836655c6a4212676c78ec96c0ac… 2024-02-21 2024-02-28
HASH 8fb6d8a5013bd3a36c605031e86fd1f… 2024-02-21 2024-02-28
HASH aec915753612bb003330ce7ffc67cfa… 2024-02-21 2024-02-28
HASH a4e4618b358c92e04fe6b7f94a11487… 2024-02-21 2024-02-28
HASH c56c94e21913b2df4be293001da84c3… 2024-02-21 2024-02-28
HASH 60c080a29f58cf861f5e7c7fc5e5bdd… 2024-02-21 2024-02-28
HASH b4a04b450bb7cae5ea578e79ae9d0f2… 2024-02-21 2024-02-28
HASH 3ab6e6fc888e4df602eff1c5bc24f3e… 2024-02-21 2024-02-28
URL https://fasttet.com/user/agency… 2024-02-21 2024-02-28
URL https://blockchain-newtech.com/… 2023-12-08 2024-02-28
URL https://chaingrown.com/manage/m… 2023-12-08 2024-02-28

Related Reports

« Back